Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,416
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-28211—25.7%
——8——CVE-2017-17280—25.7%
——8——CVE-2025-7820—25.7%
——8——CVE-2022-32537—25.7%
——8——CVE-2026-42034—25.7%
——8——CVE-2025-1074—25.7%
——8——CVE-2020-8322—25.7%
——8——CVE-2005-3647—25.7%
——8——CVE-2026-33170—25.7%
——8——CVE-2025-7953—25.7%
——8——CVE-2024-56266—25.7%
——8——CVE-2015-0162—25.7%
——8——CVE-2023-25997—25.7%
——8——CVE-2017-2730—25.7%
——8——CVE-2008-2709—25.7%
——8——CVE-2020-8323—25.7%
——8——CVE-2026-203018.6 HIG25.7%
——8A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper handling of malformed XMCP packets. An attacker could exploit this vulnerability by sending a malformed XMCP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload unexpectedly, resulting in a DoS condition. The attacker does not need the XMCP client username to exploit this vulnerability.40dCVE-2026-48588.0 HIG25.7%
——8Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which allows an malicious authenticated user to call an arbitrary API via system admin Mattermost auth token using via path traversal in integration action URL.. Mattermost Advisory ID: MMSA-2026-0064054dCVE-2026-19820—25.7%
——8A vulnerability in the Backblaze Client allows a local user to make the system not bootable by creating a link from Backblaze's folder to Windows OS system files during a backup. Successful exploitation requires an administrator-level system change that results in the absence of specific Windows OS security controls. This vulnerability is due to improper link resolution.5dCVE-2025-59504—25.7%
——8——CVE-2026-882897.5 HIG25.7%
——8GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR service.5dCVE-2024-37483—25.7%
——8——CVE-2026-30140—25.7%
——8——CVE-2024-12278—25.7%
——8——CVE-2020-25680—25.7%
——8——CVE-2026-727866.5 MED25.7%
——8Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows authenticated users to change passwords without verification. Attackers with edit users permission can reset any user's password including administrators by exploiting the unprotected newPassword field in the User element save flow.15dCVE-2025-1969—25.7%
——8——CVE-2025-57951—25.7%
——8——CVE-2023-44434—25.7%
——8——CVE-2026-728568.1 HIG25.7%
——8Budibase versions before 3.40.0 contain an authorization/authentication bypass in the PUT /api/global/users/tenant/owner (changeTenantOwnerEmail) endpoint. On self-hosted instances (SELF_HOSTED or DISABLE_ACCOUNT_PORTAL set), the cloudRestricted middleware is a no-op and the route is protected only by a general authentication check, so any authenticated user — including a lowest-privilege BASIC app user — can reassign the tenant account-holder (top-privilege admin) email to an attacker-controlled address. The attacker can then use the public password-reset flow to take over the admin account, leading to full administrative access.15dCVE-2026-49337—25.7%
——8——CVE-2024-38860—25.7%
——8——CVE-2026-7399—25.7%
——8——CVE-2025-10352—25.7%
——8——CVE-2022-46761—25.7%
——8——CVE-2025-466387.5 HIG25.7%
——8Dell BSAFE SSL-J contains an allocation of resources without limits or throttling vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to a Denial of Service (DoS).55dCVE-2025-68718—25.7%
——8——CVE-2025-57959—25.7%
——8——CVE-2025-35057—25.7%
——8——CVE-2025-11078—25.7%
——8——